Privacy Policy
Effective date: June 8, 2026 · Last updated: August 16, 2026
1. Who we are
inSpring TalentOS (the “Platform”) is operated by inSpring LLC (“inSpring”, “we”, “us”, “our”). The Platform connects candidates, universities, training institutions, and employers to support education, credentialing, work authorization, and career placement.
If you have privacy questions, contact us at:
- Email: privacy@inspringcareers.com
- Mail: PO Box 810, 48 Waterfield Road, Winchester, MA 01890
2. Information we collect
We collect information in three ways: information you give us, information we collect automatically, and information we receive from third parties (your employer, school, or recruiter).
2.1 Account & profile
When you register or are added to the Platform we collect:
- Name, email address, phone / WhatsApp number, country of residence
- Country of birth (used to determine visa pathway)
- Role (candidate, advisor, recruiter, employer representative, etc.)
- Profile photo (optional)
2.2 Documents and credentials
To support credentialing, licensure, and visa filing, candidates upload or have uploaded on their behalf:
- Transcripts and degree records
- License and certification records
- English language test results (TOEFL, IELTS, etc.)
- Credential evaluation reports
- Passports and government-issued identification
- Reference letters
- Resume / CV
- Immigration and work authorization documents (I-20, EAD, OPT, H-1B, visa stamps, etc.)
- Professional experience credentials
- Employment verification documents
These documents may include sensitive data such as date of birth and government-issued identifiers. We treat them accordingly under applicable privacy laws.
2.3 Communications
Every email, WhatsApp message, and SMS sent through the Platform — in either direction — is logged to the candidate’s record so advisors and recruiters have a unified history. This includes:
- Message content
- Sender / recipient addresses
- Subject lines, message IDs, and reply chains
- Attachments
- Delivery and read status (where available)
2.4 Course progress and assessments
If you enroll in a course or questionnaire on the Platform:
- Course completion percentages, grades, certificates
- Questionnaire responses
- Timestamps for activity, logins, and submissions
2.5 Payments
Payments are processed by Stripe. We collect:
- Stripe customer ID and payment intent identifiers
- Purchase history (item, amount, status, timestamp)
- We do not store full credit card numbers — Stripe holds those.
2.6 Hiring and placement data
When an employer partner is matched to a candidate, we collect:
- Interview rounds, notes, and outcomes
- Offer terms (where shared with us)
- Pipeline stage, sub-stage, and stage history
2.7 Interview practice calls
The Platform offers AI-led interview practice. When you take one:
- Your speech during the call is recorded and stored, where the practice session has recording enabled
- A written transcript of the call is produced and kept with your record
- Any score, pass/fail result, and reviewer feedback
Recordings and transcripts are visible to inSpring staff working on your case. They are used to give you feedback and to improve your preparation — never shared with employers unless you ask us to.
2.8 Agreements and referrals
- Agreements you sign electronically, and the signing timestamp
- If you refer a friend, the referral link between your account and theirs, and the status of any referral reward
2.9 Automatically-collected information
- Authentication events (login, logout, password reset)
- IP addresses (used for rate limiting and abuse detection; kept transiently for rate limiting, and in a security log)
- Browser / device user agent (transient — used for compatibility checks)
- Cookies necessary for keeping you logged in (no advertising cookies)
- Security and access logs. We record staff access to candidate records, sign-in events, and automated anomaly checks, so we can investigate misuse of the Platform.
- Session replay. Our error-monitoring provider records a sample of browsing sessions (roughly 1 in 10, plus sessions where an error occurs) to help us reproduce bugs. All text is masked and all images and media are blocked before the recording leaves your browser, so these replays show layout and interaction, not your content.
We do not use third-party advertising trackers and we do not sell or share your information for cross-context behavioral advertising.
3. How we use your information
We process your information to:
- Provide and operate the Platform (account creation, scheduling, document review, messaging, course delivery, employer matching)
- Communicate with you about your case (advisors, recruiters, status updates)
- Process payments
- Support work authorization and visa filing
- Match candidates to employers and academic programs
- Comply with legal obligations
- Investigate abuse, debug errors, and improve the Platform
- Send transactional emails (password resets, notifications). We do not use your information for marketing without your separate consent.
4. Third parties that receive your information
We use a small number of vendors (“sub-processors”) to operate the Platform. Each receives only the information needed for the service:
| Sub-processor | Purpose | Data shared |
|---|---|---|
| Supabase | Primary infrastructure (database, auth, storage) | All Platform data |
| Vercel | Application hosting | Request metadata; no persistent data storage |
| Stripe | Payment processing | Name, email, payment details |
| Resend | Transactional and reply email | Sender / recipient, subject, body, attachments |
| Meta Platforms | WhatsApp message delivery; Facebook and Instagram lead ad forms, whose answers we import to create your record | Recipient phone number, message body, any attached media; whatever you enter into a Facebook or Instagram lead form |
| SimpleTexting | SMS delivery (US and Canada) | Recipient phone number, message body |
| Canvas LMS (Instructure) | Course enrollment and training-progress tracking | Name, email, course enrollment and progress data |
| Anthropic (Claude) | AI features (see Section 5) | Resume text, interview transcripts, optional report prompts |
| Sentry | Error monitoring and session replay | Error stack traces, request paths, masked session recordings (see 2.9) |
| Vapi | Runs the AI interview-practice voice calls | Your speech during a practice call, the resulting transcript, the question set |
| Daily.co | Real-time audio transport underneath Vapi | Live call audio in transit; no persistent storage |
| Cloudflare R2 | Storage for practice-call recordings | Recorded audio of practice interviews |
| Cloudflare Turnstile | Bot protection on sign-up and lead forms | IP address and browser signals at submission time |
| BoldSign | Electronic signature of agreements | Name, email, the agreement document, signing events |
| Calendly | Meeting scheduling with advisors and recruiters | Name, email, meeting time and event type |
| Upstash | Rate limiting and abuse prevention | IP address, expiring within the hour |
| Squarespace | Hosts the campaign landing pages whose forms create leads | Whatever you enter into a campaign form |
Each sub-processor receives only what its service requires. All of them store data in, or route it through, the United States — see Section 6.
4.1 Contractual position
We rely on each vendor’s standard terms of service and published data processing terms. We have not negotiated bespoke data processing agreements with these vendors. For most of this list that is the ordinary arrangement — the major infrastructure and communications vendors publish data processing terms that are incorporated into their standard agreement and apply on acceptance, without a separate signature.
4.2 Changes to this list
Before a new vendor receives candidate data, we add it to the table above and give any new data category a retention period in the Data Retention Policy. Questions about any vendor listed here: privacy@inspringcareers.com.
4.3 Others we share with
Beyond the vendors above, we may share information with:
- Employer partners when you are placed in their pipeline, limited to what they need to make hiring decisions.
- Academic / school partners when you are enrolled in their program.
- Recruiter partners working on your placement.
- Law enforcement / regulators, where required by law and after a legal review.
We do not sell your information.
5. AI processing notice
Three features on the Platform send your data to Anthropic’s Claude API:
- Resume parsing. When you upload a resume during a questionnaire, the text is sent to Anthropic to extract structured fields (employer history, dates, certifications). Up to 30,000 characters of resume content are sent per parse. Before any data is sent, you must check an explicit consent box confirming you understand your resume text will be processed by Anthropic’s AI. Your consent choice and timestamp are recorded.
- AI custom reports (admin-only). Admins may write natural-language prompts that are sent to Anthropic to generate database queries. Prompts may reference candidate names; the schema is shared but candidate row data is not sent to Anthropic — only the resulting query is run on our side.
- Interview practice scoring. The transcript of an AI practice call is sent to Anthropic to produce a score and written feedback against the questions you were asked.
Our Anthropic account is configured for zero data retention, and your data is not used to train models. This is a configuration setting on our account rather than a guarantee we can make on Anthropic’s behalf; their own terms govern what they do with API traffic.
Every call to Anthropic’s API is recorded in an internal audit log that captures: which feature was used, the data categories involved, input/output size, the user who triggered it, whether consent was given, and the timestamp.
You can ask us to remove your resume’s parsed output at any time by emailing privacy@inspringcareers.com.
6. International transfers
inSpring serves candidates from many countries while operating infrastructure that is primarily US-hosted. As a result, your information will be transferred to and stored in the United States. Where applicable transfer mechanisms (e.g., Standard Contractual Clauses for EU/UK users) apply, we rely on them.
7. Data retention
We keep your information only as long as we need it. Target retention windows by category are described in our Data Retention Policy, which is part of this Privacy Policy by reference. Deletion of expired records is currently carried out on request and by periodic review rather than automatically; the retention policy says which parts are automated today.
If you ask us to delete your account, we will delete or de-identify your information within 30 days, except where we are required to keep records for legal, tax, or anti-fraud purposes. Backups containing your information may persist for up to 90 days after deletion before they are overwritten.
8. Your rights
Depending on where you live, you may have the right to:
- Access the information we hold about you
- Correct information that is inaccurate
- Delete your information (“right to erasure”)
- Object to or restrict certain processing
- Receive a copy of your data in a portable format
- Withdraw consent for processing that relies on consent
- Lodge a complaint with your local data protection authority
To exercise any of these, email privacy@inspringcareers.com. We will respond within 30 days.
We will not retaliate against anyone for exercising their privacy rights.
9. Security
We protect your information with:
- Encryption in transit (TLS) and at rest
- Role-based access controls and row-level database security
- Authentication via Supabase Auth with bcrypt-hashed passwords
- Audit logging of administrative and AI-report queries
- External error monitoring so production failures are caught quickly
- A documented backup and restore procedure with point-in-time recovery
No system is perfectly secure. If we ever experience a breach affecting your information, we will notify you and the relevant regulators in accordance with applicable law.
10. Children’s privacy
The Platform is intended for users aged 18 and older. We do not knowingly collect information from anyone under 18. If you believe we have, contact us and we will delete it.
11. Changes to this policy
We may update this policy as the Platform evolves. Material changes will be communicated by email at least 14 days before they take effect. The effective date at the top of this page reflects the most recent change.
12. Consent acknowledgement
By creating an account on the Platform, or by continuing to use the Platform after the effective date above, you acknowledge that you have read this Privacy Policy and consent to the processing described. Specific operations that require additional explicit consent (e.g., AI resume parsing) will surface their own consent prompts.